Cover photo

What a Public-Surface Authority Review Actually Proves

A detector can observe authority evidence. It cannot prove operational control.

The first question in protocol continuity is not whether a contract has an owner.

It is what that owner can do, what controls the owner, and what evidence exists when that authority path is stressed.

A public-surface authority review starts with what can be observed: owner calls, proxy slots, timelocks, multisigs, role surfaces, oracle paths, source and ABI status, and public governance context.

But observation is not assurance.

A detector can identify an authority surface. It cannot prove custody practice, signer independence, upgrade approval policy, emergency response, or governance intent. That evidence boundary is the foundation of Sagitta’s Defense Review method.

Public evidence is useful. It is not complete.

Onchain systems expose a lot.

A contract may expose an owner() call. A proxy may expose an implementation slot or admin slot. A Safe may expose owners and a threshold. A timelock may expose a delay. An oracle contract may expose feed behavior. A role system may expose part of its access-control structure.

Those are real observations.

They matter.

But each observation only proves what it was designed to observe.

An owner() call proves that an owner address was observed through a supported public call. It does not prove who controls that owner, whether the signer policy is sound, whether key rotation exists, or whether the emergency replacement process is usable.

A proxy admin slot can show where upgrade authority points. It does not prove that upgrades require the right approval process.

A timelock delay can show that execution is delayed. It does not prove governance intent, cancellation policy, emergency bypass policy, or which contracts are meaningfully protected by that timelock.

A Safe threshold can show the public signer structure. It does not prove signer independence, operational readiness, module risk, or incident response discipline.

That is the difference between evidence and assurance.

The mistake is treating visibility as verification.

Many protocol reviews collapse these ideas.

  • They see an owner and assume the authority path is understood.

  • They see a timelock and assume governance is safe.

  • They see a multisig and assume operational control is mature.

  • They see verified source and assume control design is verified.

That is not how continuity works. Continuity risk often lives between what a contract exposes and how a team actually operates it.

The public surface can tell us what exists. It can show where authority points. It can reveal proxy paths, admin paths, role paths, oracle dependencies, and unresolved control surfaces. But it cannot prove the private operating layer by itself.

That layer requires evidence.

Signer policy. Upgrade policy. Treasury movement policy. Timelock execution policy. Oracle fallback policy. Emergency pause policy. Governance execution process. Role inventory. Incident response ownership.

Without that evidence, the honest answer is not “safe” or “unsafe.”

The honest answer is: evidence required.

Evidence required is not a failed control.

This matters.

When Sagitta marks something as evidence required, that does not mean the protocol failed. It means the public surface does not prove the operating control.

That distinction keeps the review honest.

A Defense Review should not inflate severity just because evidence is missing. It should not turn unresolved authority into a vulnerability claim. It should not imply exploitability without proof. It should not treat source, ABI, graph, or detector output as control verification by itself.

The job is to separate what was observed, what was inferred, what remains unresolved, and what evidence is required before a control can be reviewed.

That is the discipline.

The four evidence states

Sagitta’s public-surface method uses a simple evidence model.

  1. Observed means a specific public evidence item resolved through a supported call, storage slot, or verified source/ABI path.

  2. Inferred means the review has a reasonable pattern or metadata basis, but the evidence is not complete enough to treat as directly verified.

  3. Unresolved means an in-scope authority surface exists, but SCE could not resolve the path with enough confidence from the available evidence.

  4. Evidence Required means the protocol team needs to provide policy, signer, governance, role, source, ABI, or operating evidence before that control can be reviewed for verification.

This model keeps the review useful without pretending to know more than the evidence supports.

Why this matters for protocol continuity

Protocol failure is rarely just about one contract. It is usually about paths.

  • Who can upgrade the system?

  • Who can pause it?

  • Who can move treasury funds?

  • Who can change the oracle?

  • Who can change implementation logic?

  • Who can execute governance?

  • Who can act during an emergency?

  • Who watches the timelock window?

  • Who owns the fallback path?

A project map turns those questions into a reviewable surface. It connects contracts, proxies, implementations, admins, timelocks, Safes, governors, oracles, treasuries, keepers, and linked candidates into one authority picture.

That picture is not the same as an audit.

An audit looks deeply at code behavior and exploit paths.

A Defense Review looks at whether the system can survive control failure.

Both matter. They answer different questions.

What a public-surface authority review actually proves

  • It proves what can be observed.

  • It proves which authority surfaces were visible.

  • It proves which detector methods resolved public evidence.

  • It proves which paths remain unresolved.

  • It proves which operating evidence is needed before a protocol can claim stronger continuity readiness.

That is enough to be valuable.

Not because it declares the protocol safe. Because it gives the team a clearer map of what still needs to be proven. That is the point of The Continuity Desk.

  • Not to create noise.

  • Not to dress up scanner output.

  • Not to turn missing evidence into fear.

The work is to make authority evidence legible.

Teams preparing for launch, treasury growth, protocol upgrades, or governance changes can request a Sagitta Defense Review to map public authority surfaces, unresolved control paths, and evidence gaps before those paths are stressed.

The Continuity Desk is published by Sagitta Continuity Engine.
Protocol authority and continuity research from Sagitta.